๐บ๐ธ
TPI-Abuse
2026-10-01 19:21:49
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.19.215.214 (214.215.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.215.214 (214.215.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 15:21:42.039139 2026] [security2:error] [pid 14352:tid 14352] [client 34.19.215.214:49974] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||test.ankitoner.com|F|2"] [data ".ankitoner.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "test.ankitoner.com"] [uri "/z9x8c7v6b5-debug-trigger-test.ankitoner.com"] [unique_id "ar6yxvWf8DyrchmO7AtOsAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
n2nguyenn2nguyen
2026-10-01 18:05:27
(2 hours ago)
Blocked by YFC Security on https://1904.brixzly.com โ type: directory_scan_attempts
Web App Attack
Anonymous
2026-10-01 17:56:12
(2 hours ago)
Bot / seems abusive / Apache connections: 29
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 17:39:24
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.215.214 (214.215.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.215.214 (214.215.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:39:20.554524 2026] [security2:error] [pid 4919:tid 4919] [client 34.19.215.214:54274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.actability.com"] [uri "/.git/config"] [unique_id "ar6ayLugQqWzhF6sIFQlogAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 17:21:13
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.215.214 (214.215.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.215.214 (214.215.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:21:05.653872 2026] [security2:error] [pid 20253:tid 20253] [client 34.19.215.214:33586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.arogun.org"] [uri "/assets../.env"] [unique_id "ar6Wgd04a9o8ogc8QnHR4AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 16:58:50
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.215.214 (214.215.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.215.214 (214.215.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:58:42.648163 2026] [security2:error] [pid 32756:tid 32756] [client 34.19.215.214:46586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.alexsource.com"] [uri "/media../.env"] [unique_id "ar6RQiX7WW36k_y3xpH9TgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
infra-monitor
2026-10-01 16:00:09
(4 hours ago)
Automated ban via infra-monitor: suspicious-probe, crowdsecurity/http-admin-interface-probing, crowd ...
show more
Automated ban via infra-monitor: suspicious-probe, crowdsecurity/http-admin-interface-probing, crowdsecurity/http-sensitive-files, +2 more
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:55:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.215.214 (214.215.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.215.214 (214.215.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:54:52.569949 2026] [security2:error] [pid 20680:tid 20680] [client 34.19.215.214:53008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.almudenastrust.com"] [uri "/.//.env"] [unique_id "ar6CTCKhvn6lxFkK6VbrgwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:28:33
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.19.215.214 (214.215.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.215.214 (214.215.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:28:29.631025 2026] [security2:error] [pid 26848:tid 26863] [client 34.19.215.214:55674] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.andrewbelschner.com|F|2"] [data ".andrewbelschner.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.andrewbelschner.com"] [uri "/z9x8c7v6b5-debug-trigger-www.andrewbelschner.com"] [unique_id "ar58HcQwJu-C9w5Ju4DpcwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oralunal
2026-10-01 14:51:45
(6 hours ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:51:17
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.19.215.214 (214.215.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.215.214 (214.215.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:51:12.647643 2026] [security2:error] [pid 13916:tid 13916] [client 34.19.215.214:54548] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||web118.dnchosting.com|F|2"] [data ".dnchosting.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "web118.dnchosting.com"] [uri "/z9x8c7v6b5-debug-trigger-web118.dnchosting.com"] [unique_id "ar5zYBhwqznsQOoAT-uZOwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 14:44:52
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.19.215.214 (CA/Canada/214.215.19.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.19.215.214 (CA/Canada/214.215.19.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-01 13:13:54
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.215.214 (214.215.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.215.214 (214.215.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:13:50.059198 2026] [security2:error] [pid 6415:tid 6415] [client 34.19.215.214:50126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.929.us"] [uri "/.env.js"] [unique_id "ar5cjpvKPcF5AyfOQ0cO_wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-10-01 11:21:24
(9 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: actuator, ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: actuator, ignition_debug, server_status, env_probe, path_traversal, source_backup, aws_creds, git_exposure. Observed by 1 sensor(s); 883 hits.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:17:25
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.215.214 (214.215.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.215.214 (214.215.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:17:20.873783 2026] [security2:error] [pid 26551:tid 26551] [client 34.19.215.214:44878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.alanmariotti.com"] [uri "/wp-config.php.old"] [unique_id "ar5BQFUySxqUfZVNOQ3isQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack